Show filters
360 Total Results
Displaying 51-60 of 360
Sort by:
Attacker Value
Unknown
CVE-2023-4801
Disclosure Date: September 13, 2023 (last updated October 08, 2023)
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected.
0
Attacker Value
Unknown
CVE-2023-28415
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XootiX Side Cart Woocommerce (Ajax) plugin <= 2.2 versions.
0
Attacker Value
Unknown
CVE-2023-2110
Disclosure Date: August 19, 2023 (last updated February 25, 2025)
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.
0
Attacker Value
Unknown
CVE-2023-31091
Disclosure Date: August 17, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.
0
Attacker Value
Unknown
CVE-2020-36747
Disclosure Date: July 01, 2023 (last updated November 09, 2023)
The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the metabox_save() function. This makes it possible for unauthenticated attackers to save metbox data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-36002
Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.
0
Attacker Value
Unknown
CVE-2023-36000
Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
0
Attacker Value
Unknown
CVE-2023-35998
Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
0
Attacker Value
Unknown
CVE-2023-2818
Disclosure Date: June 27, 2023 (last updated February 25, 2025)
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffected.
0
Attacker Value
Unknown
CVE-2023-0489
Disclosure Date: June 19, 2023 (last updated October 08, 2023)
The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
0